39 1 (ii) in a manner that protects from 2 unauthorized use or disclosure any cyber 3 threat indicators that may contain personal 4 information or information that identifies 5 specific persons; and 6 (iii) in a manner that protects the 7 confidentiality of cyber threat indicators 8 containing personal information or infor- 9 mation that identifies a specific person. 10 (D) FEDERAL 11 (i) IN REGULATORY AUTHORITY.— GENERAL.—Except as provided 12 in clause (ii), cyber threat indicators and 13 defensive measures provided to the Federal 14 Government under this title shall not be 15 directly used by any Federal, State, tribal, 16 or local government to regulate, including 17 an enforcement action, the lawful activities 18 of any entity, including activities relating 19 to monitoring, operating defensive meas- 20 ures, or sharing cyber threat indicators. 21 (ii) EXCEPTIONS.— 22 (I) REGULATORY AUTHORITY 23 SPECIFICALLY RELATING TO PREVEN- 24 TION OR MITIGATION OF CYBERSECU- 25 RITY THREATS.—Cyber † S 754 ES threat indica-

Select target paragraph3